Peak6Group

Peak6Group

Identity Access Manager (IAM) Engineer

Chicago, IL

Sponsorship not specified$104k-$130kDetected 13 days ago
AWSGCPOAuthCybersecurityJiraAuditingCadenceCommunicationCompTIA

About the role

  • That means making sure the right people have the right access at the right time, and that attackers cannot abuse credentials, tokens, or access paths to move through our environment.
  • PEAK6 operates across financial services, broker-dealer, insurance, and technology sectors.

Responsibilities

  • Harden privileged access: deploy and validate phishing-resistant MFA for admin accounts (FIDO2/WebAuthn hardware keys or equivalent), maintain break-glass account procedures and test them on a defined cadence, and enforce least-privilege baselines across cloud and SaaS environments.
  • Own OAuth hygiene: audit and clean up risky or overprivileged OAuth grants across Google Workspace and connected SaaS platforms
  • Build and operate JML automation: design and implement joiner, mover, and leaver workflows with evidence trails
  • drive leaver access revocation to a consistent sub-24-hour SLA and mover access delivery within defined SLAs.
  • Apply risk-based access controls: define and implement stronger authentication and higher-scrutiny monitoring for risk cohorts (executives, finance, and IT admins) in partnership with the identity platform owners.
  • Maintain continuous IAM visibility: build and sustain reporting that makes access posture visible (stale accounts, standing privilege, risky grants, and JML exceptions) and route findings to owners with Jira-tracked SLAs.
  • Partner on identity-adjacent controls: coordinate with the Cloud/Platform team on cloud IAM policy, admin MFA enforcement, and least-privilege baselines across AWS and GCP environments.
  • Document and prove outcomes: maintain runbooks, process documentation, and evidence records that support audit inquiries, access certifications, and executive reporting.

Requirements

  • familiarity with break-glass patterns, MFA enforcement policies, and admin account separation
  • experience with an enterprise password/secrets manager (we use 1Password).

Nice to have

  • designing or operating joiner/mover/leaver workflows, ideally with evidence trails and measurable SLA tracking.
  • Leaver access is revoked consistently within 24 hours with clean evidence trails.
  • Admin accounts have phishing-resistant MFA enforced and break-glass procedures are tested and documented.
  • Risky OAuth grants are identified, assessed, and resolved on a defined cadence, with a visible reduction in high-risk delegated access over time.

Compensation

  • $104,000-$130,000
  • Base Salary Range

Benefits

  • We offer a robust package of employee perks and benefits, including healthcare benefits (medical, dental and vision, EAP), competitive PTO, 401k match, parental leave, and HSA contribution match.
  • We also provide our employees with a paid subscription to the Calm app and offer generous external learning and tuition reimbursement benefits.
  • This position also may be eligible for a discretionary annual bonus in addition to a range of health & wellness benefits, enhancing your overall compensation package.

Company info

  • We are PEAK6, a leading investment firm, using technology to find a better way of doing things.
  • The company's first tech-based solution was developed in 1997 to optimize options trading, and over the past two decades, the same formula has been used across a range of industries, asset classes, and business stages to consistently deliver superior results.
  • Today, PEAK6 seeks transformational opportunities to provide capital and strategic support to entrepreneurs and forward-thinking businesses.
  • PEAK6's core brands include PEAK6 Capital Management, PEAK6 Strategic Capital, Apex Fintech Solutions, FOCUS, We Insure, Evil Geniuses, Poker Power, Zogo, and Bruce Markets.
  • We are dedicated to ensuring equal employment opportunities and providing reasonable accommodations to qualified individuals with disabilities.
  • As a hybrid workforce, we offer our employees the ability to work remotely up to two days a week.

This listing is sourced directly from Peak6Group's careers page and normalized into a canonical job model.